Flexible authentication
Abstract
Provided is dynamic and flexible authentication based on an interaction over a communications link between a user device and a financial entity. A set of interactions enabled at the user device are categorized into different levels, each level comprises a different authentication policy. At about the same time as an interaction is initiated at the device, an authentication policy assigned to the interaction is accessed and a security challenge is activated at the device. Based upon a successful response to the security challenge, an enablement of the communications link is continued. Based upon an unsuccessful response to the security challenge, the communications link is disabled.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method, comprising:
categorizing, by a system comprising a processor, a set of financial interactions into different levels of authentication; designating, by the system, an authentication policy for each level of authentication, wherein each level of authentication is designated with a different authentication policy; evaluating, by the system, an interaction of the set of financial interactions being performed at a device, wherein the interaction is performed over a communication link enabled between a financial entity and the device, and wherein evaluating the interaction includes:
assigning a risk level to the interaction, wherein the risk level is based on whether the interaction indicates an anomaly relative to a historical pattern of interactions previously performed by the device,
assigning a confidence level to the interaction, wherein the confidence level is based on a characteristic of the device or an indicator of an identity of a user of the device, and
assigning, for the interaction, a level of authentication based on the assigned risk level and confidence level, wherein assigning the level of authentication includes: (i) identifying a set of rules associated with the interaction, the set of rules being defined by a matrix; (ii) selecting, from the matrix, a rule of the set of rules based on the assigned risk level and confidence level; and (iii) applying the rule to the interaction to determine at least one type of authentication required to authenticate the device before approving the interaction;
as a result of the evaluating, causing a security challenge to be output at the device, wherein the security challenge comprises a prompt to perform a set of passive and active actions, wherein the set of passive and active actions are determined based on the at least one type of authentication identified by the level of authentication, wherein a passive action of the set of passive and active actions identifies an action to be performed by the device without user input, and wherein an active action of the set of passive and active actions identifies an action to beperformed by the user of the device; receiving, from the device, a response to the security challenge, wherein the response includes results indicative of whether the set of passive and active actions have been successfully performed; authenticating the user of the device based on the results of the set of passive and active actions meeting a predetermined threshold for the level of authentication; and approving, by the system, performance of the interaction at the device based on authenticating the user.
2 . The method of claim 1 , wherein approving performance of the interaction comprises continuing the enablement of the communications link between the device and the financial entity as a function of an expected response to the security challenge.
3 . The method of claim 1 , wherein not approving performance of the interaction comprises disabling the communications link between the device and the financial entity based on an unexpected response to the security challenge.
4 . The method of claim 1 , wherein assigning a confidence level to the interaction further comprises:
determining a location where initiation of the interaction occurs; and evaluating historical information associated with the location.
5 . The method of claim 1 , wherein the prompt to perform the set of passive and active actions includes a request for biometric identification from the user.
6 . A non-transitory computer-readable storage device storing executable instructions that, in response to execution, cause a system comprising a processor to perform operations, the operations comprising:
categorizing a set of financial interactions into different levels of authentication; designating an authentication policy for each level of authentication, wherein each level of authentication is designated with a different authentication policy; evaluating an interaction of the set of financial interactions being performed at a device, wherein the interaction is performed over a communication link enabled between a financial entity and the device, and wherein evaluating the interaction includes:
assigning a risk level to the interaction, wherein the risk level is based on whether the interaction indicates an anomaly relative to a historical pattern of interactions previously performed by the device,
assigning a confidence level to the interaction, wherein the confidence level is based on a characteristic of the device or an indicator of an identity of a user of the device, and
assigning, for the interaction, a level of authentication based on the assigned risk level and confidence level, wherein assigning the level of authentication includes: (i) identifying a set of rules associated with the interaction, the set of rules being defined by a matrix; (ii) selecting, from the matrix, a rule of the set of rules based on the assigned risk level and confidence level; and (iii) applying the rule to the interaction to determine at least one type of authentication required to authenticate the device before approving the interaction;
as a result of the evaluating, causing a security challenge to be output at the device, wherein the security challenge comprises a prompt to perform a set of passive and active actions, wherein the set of passive and active actions are determined based on the at least one type of authentication identified by the level of authentication, wherein a passive action of the set of passive and active actions identifies an action to be performed by the device without user input, and wherein an active action of the set of passive and active actions identifies an action to be performed by the user of the device; receiving, from the device, a response to the security challenge, wherein the response includes results indicative of whether the set of passive and active actions have been successfully performed; authenticating the user of the device based on the results of the set of passive and active actions meeting a predetermined threshold for the level of authentication; and approving performance of the interaction at the device based on authenticating the user.
7 . The computer-readable storage device of claim 6 , wherein the operations further comprise requesting a third party token or a biometric identification as at least a portion of the security challenge.
8 . The computer-readable storage device of claim 6 , wherein the operations further comprise requesting a third party token and a biometric identification as at least a portion of the security challenge.
9 . The computer-readable storage device of claim 6 , wherein the prompt to perform the set of passive and active actions includes a request for biometric identification from the user.
10 . A system, comprising:
a memory that stores executable code and a processor configured to execute the executable code, and upon execution causes:
categorizing a set of financial interactions into different levels of authentication;
designating an authentication policy for each level of authentication, wherein each level of authentication is designated with a different authentication policy;
evaluating an interaction of the set of financial interactions being performed at a device, wherein the interaction is performed over a communication link enabled between a financial entity and the device, and wherein evaluating the interaction includes:
assigning a risk level to the interaction, wherein the risk level is based on whether the interaction indicates an anomaly relative to a historical pattern of interactions previously performed by the device,
assigning a confidence level to the interaction, wherein the confidence level is based on a characteristic of the device or an indicator of an identity of a user of the device, and
assigning, for the interaction, a level of authentication based on the assigned risk level and confidence level, wherein assigning the level of authentication includes: (i) identifying a set of rules associated with the interaction, the set of rules being defined by a matrix; (ii) selecting, from the matrix, a rule of the set of rules based on the assigned risk level and confidence level; and (iii) applying the rule to the interaction to determine at least one type of authentication required to authenticate the device before approving the interaction;
as a result of the evaluating, causing a security challenge to be output at the device, wherein the security challenge comprises a prompt to perform a set of passive and active actions, wherein the set of passive and active actions are determined based on the at least one type of authentication identified by the level of authentication, wherein a passive action of the set of passive and active actions identifies an action to be performed by the device without user input, and wherein an active action of the set of passive and active actions identifies an action to be performed by the user of the device; receiving, from the device, a response to the security challenge, wherein the response includes results indicative of whether the set of passive and active actions have been successfully performed; authenticating the user of the device based on the results of the set of passive and active actions meeting a predetermined threshold for the level of authentication; and approving performance of the interaction at the device based on authenticating the user.
11 . The system of claim 10 , wherein approving performance of the interaction comprises continuing the enablement of the communications link between the device and the financial entity as a function of an expected response to the security challenge.
12 . The system of claim 10 , wherein not approving performance of the interaction comprises disabling the communications link between the device and the financial entity based on an unexpected response to the security challenge.
13 . The system of claim 10 , wherein assigning a confidence level to the interaction further comprises:
determining a location where initiation of the interaction occurs; and evaluating historical information associated with the location.
14 . The system of claim 10 , wherein the prompt to perform the set of passive and active actions includes a request for biometric identification from the user.Join the waitlist — get patent alerts
Track US11816672B1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.